PT-2008-6760 · Slimcms · Slimcms
Staker
·
Publicado
2008-12-24
·
Atualizado
2017-09-29
·
CVE-2008-5708
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SlimCMS version 1.0.0
Description
The issue allows remote attackers to create administrative users without requiring authentication. This can be achieved by utilizing the
newusername and newpassword parameters and setting the newisadmin parameter to 1 in the 'redirect.php' file.Recommendations
For SlimCMS version 1.0.0, consider restricting access to the 'redirect.php' file until a patch is available, or apply authentication requirements to this file to prevent unauthorized user creation.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Slimcms